Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Update Jira REST Java Client for security

sebastian_de
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
July 15, 2020

Hi,

we are using the Jira REST Java Client (JRJC) in the newest version (5.2.1). Thanks for providing such an extensive client!

The client brings the dependency com.sun.jersey:jersey-client with it in version 1.19.

Jersey moved to a new group id: org.glassfish.jersey.core:jersey-client which is available in 2.31.

The problem with the com.sun.jersey:jersey-client is that it brings org.codehaus.jackson:jackson-mapper-asl (version 1.9.2) with it which has multiple vulnerabilities (CVE-2018-14718, CVE-2018-5968, CVE-2020-10673, CVE-2018-7489, CVE-2019-14540, CVE-2019-14893, CVE-2017-17485, CVE-2018-1000873).

Is there any chance you upgrade to a new version of jersey-client to fix these security incidents?

Thanks!
Sebastian 

2 answers

0 votes
Robert Winterfeld
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
December 14, 2021

what is the current status of the request, unfortunately I cannot read it

0 votes
Debeka Support
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
October 19, 2021

Hi Sebastian,

I contacted the Atlassian support and they created an issue:

https://jira.atlassian.com/browse/JRASERVER-72920

Best regards

Alexander

Robert Winterfeld
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
December 14, 2021

what is the current status of the request, unfortunately I cannot read it

Like # people like this

Suggest an answer

Log in or Sign up to answer